Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Invalid SPDX document #394

Open
nikpivkin opened this issue Mar 20, 2024 · 1 comment
Open

Invalid SPDX document #394

nikpivkin opened this issue Mar 20, 2024 · 1 comment

Comments

@nikpivkin
Copy link

Hi!

The SPDX document that is written to the image is not valid because some required fields are missing:

The following warning(s) were raised:
[object has missing required properties (["creationInfo","dataLicense"]) for {"pointer":""}, object has missing required properties (["downloadLocation"]) for {"pointer":"/packages/0"}, Missing required Creator, Missing required data license, Document must have at least one relationship of type DOCUMENT_DESCRIBES]

Validation tool: https://tools.spdx.org/app/validate/

@yosifkit
Copy link
Contributor

It is not meant to be consumed as-is, but extracted and expanded with a tool like Syft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants